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IN THE CLAIMS 

For the convenience of the Examiner, all pending claims of the present Application 
are shown below. 

1 . (Previously presented) A method for restoring a computer system modified 
by malicious code, comprising: 

scanning the computer system for the malicious code; 
identifying the malicious code; 

retrieving from a data file, information relating to the malicious code including at 
least one command used for restoring the computer system to a state that existed prior to 
modification by the malicious code; and 

executing the at least one command to restore the computer system to the state as the 
computer system existed prior to modification by the malicious code, wherein the at least one 
command is used for restoring at least a portion of the computer system other than a host file 
having the malicious code to the state that existed prior to the portion of the computer system 
having been modified by the malicious code. 

2. (Original) The method of claim 1, wherein the step of executing the at least 
one command includes one of reading, writing, and deleting data. 

3. (Original) The method of claim 1, wherein the step of executing the at least 
one command includes at least one of renaming and deleting a file. 

4. (Original) The method of claim 1, wherein the malicious code modifies at 
least one file and said method comprises: 

reading from the modified file, a name of a second file; and 
modifying the second file. 
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5. (Original) The method of claim 1 5 wherein the data file comprises a plurality 
of data files, each data file being provided for a particular type of malicious code, each data 
file including at least one command that can be used for restoring the computer system to a 
state that existed prior to modification by the particular type of malicious code. 
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6. (Previously presented) A storage medium computer executable code for 
restoring a computer system modified by malicious code, comprising: 

code for scanning the computer system for the malicious code; 
code for identifying the malicious code; 

code for retrieving from a data file, information relating to the malicious code 
including at least one command used for restoring the computer system to a state that existed 
prior to modification by the malicious code; and 

code for executing the at least one command to restore the computer system to the 
state as the computer system existed prior to modification by the malicious code, wherein the 
at lest one command is used for restoring at least a portion of the computer system other than 
a host file having the malicious code to the state that existed prior to the portion of the 
computer system having been modified by the malicious code. 

7. (Previously presented) The storage medium of claim 6, wherein the code for 
executing the at least one command includes code for performing at least one of reading, 
writing, and deleting data. 

8. (Original) The storage medium of claim 6, wherein the code for executing 
the at least one command includes code for performing at least one of renaming and deleting 
a file. 

9. (Original) The storage medium of claim 6, wherein the malicious code 
modifies at lest one file, said storage medium further comprising: 

code for reading from the modified file, a name of a second file; and 
code for modifying the second file. 

10. (Original) The storage medium of claim 6, wherein the data file comprises a 
plurality of data files, each data file being provided for a particular type of malicious code, 
each data file including at least one command that can be used for restoring the computer 
system to a state that existed prior to modification by the particular type of malicious code. 
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1 1 . (Previously presented) A computer data signal embodied in a transmission 
medium and including computer executable instructions for restoring a computer system 
modified by malicious code, comprising: 

a data signal portion for scanning the computer system for the malicious code; 
a data signal portion for identifying the malicious code; 

a data signal portion for retrieving from a data file, information relating to the 
malicious code including at least one command used for restoring the computer system to a 
state that existed prior to modification by the malicious code; and 

a data signal portion for executing the at least one command to restore the computer 
system to the state as the computer system existed prior to modification by the malicious 
code, wherein the at least one command is used for restoring at least a portion of the 
computer system other than a host file having the malicious code to the state that existed prior 
to the portion of the computer system having been modified by the malicious code. 

12. (Original) The computer data signal of claim 11, wherein the data signal 
portion for executing the at least one command performs at least one of reading, writing, and 
deleting data. 

13. (Original) The computer data signal of claim 11, wherein the data signal 
portion for executing the at least one command performs at least one of renaming and 
deleting a file. 

14. (Original) The computer data signal of claim 11, wherein the malicious code 
modifies at least one file, said computer data signal further comprising: 

a data signal portion for reading from the modified file, a name of a second file; and 
a data signal portion for modifying the second file. 
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15. (Original) The computer data signal of claim 11, wherein the data file 
comprises a plurality of data files, each data file being provided for a particular type of 
malicious code, each data file including at least one command that can be used for restoring 
the computer system to a state that existed prior to modification by the particular type of 
malicious code. 
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16. (Previously presented) A programmed computer system including a program 
for restoring a computer system modified by malicious code, comprising: 

means for scanning the computer system for the malicious code; 
means for identifying the malicious code; 

means for retrieving from a data file, information relating to the malicious code 
including at least one command used for restoring the computer system to a state that existed 
prior to modification by the malicious code; and 

means for executing the at least one command to restore the computer system to the 
state as the computer system existed prior to modification by the malicious code, wherein the 
at least one command is used for restoring at least a portion of the computer system other 
than a host file having the malicious code to the state that existed prior to the portion of the 
computer system having been modified by the malicious code. 

17. (Original) The programmed computer system of claim 16, wherein the means 
for executing the at least one command includes means for performing at least one of reading, 
writing, and deleting data. 

18. (Original) The programmed computer system of claim 16, wherein the means 
for executing the at least one command includes means for performing at least one of 
renaming and deleting a file. 

19. (Original) The programmed computer system of claim 16, wherein the 
malicious code modifies at least one file and said system further comprises: 

means for reading from the modified file, a name of a second file; and 
means for modifying the second file. 

20. (Original) The programmed computer system of claim 16, wherein the data 
file comprises a plurality of data files, each data file being provided for a particular type of 
malicious code, each data file including at least one command that can be used for restoring 
the computer system to a state that existed prior to modifications by the particular type of 
malicious code. 
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21. (Previously presented) The method of claim 1, wherein the information 
relating to the malicious code further comprises at least one command for curing a file 
infected with the malicious code. 

22. (Previously presented) The storage medium of claim 6, wherein the 
information relating to the malicious code further comprises at least one command for curing 
a file infected with the malicious code. 

23. (Previously presented) A computer signal of claim 11, wherein the 
information relating to the malicious code further comprises at least one command for curing 
a file infected with the malicious code. 

24. (Previously presented) A programmed computer system of claim 16, 
wherein the information relating to the malicious code further comprises at least one 
command for curing a file infected with the malicious code. 
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25. (Previously presented) The method of claim 1, wherein executing the at least 
one command comprises modifying a registry file. 

26. (Previously presented) The method of claim 1, wherein executing the at least 
one command comprises stopping a process. 

27. (Previously presented) The storage medium of claim 6, wherein the code for 
executing the at least one command includes code for modifying a registry file. 

28. (Previously presented) The storage medium of claim 6, wherein the code for 
executing the at least one command includes code for stopping a process. 

29. (Previously presented) The computer data signal of claim 11, wherein the 
data signal portion for executing the at least one command modifies a registry file. 

30. (Previously presented) The computer data signal of claim 11, wherein the 
data signal portion for executing the at least one command stops a process. 

31. (Previously presented) The programmed computer system of claim 16, 
wherein the means for executing the at least one command includes means for modifying a 
registry file. 

32. (Previously presented) The programmed computer system of claim 16, 
wherein the means for executing the at least one command includes means for stopping a 
process. 

33. (Canceled) 
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